Show filters
48 Total Results
Displaying 1-10 of 48
Sort by:
Attacker Value
Unknown

CVE-2020-35735

Disclosure Date: December 29, 2020 (last updated February 22, 2025)
Vidyo 02-09-/D allows clickjacking via the portal/ URI.
Attacker Value
Unknown

CVE-2020-28218

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.
Attacker Value
Unknown

CVE-2020-26962

Disclosure Date: December 09, 2020 (last updated February 22, 2025)
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.
Attacker Value
Unknown

CVE-2020-26953

Disclosure Date: December 09, 2020 (last updated February 22, 2025)
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Attacker Value
Unknown

CVE-2020-9945

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing.
Attacker Value
Unknown

CVE-2020-9942

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.
Attacker Value
Unknown

CVE-2020-9993

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.
Attacker Value
Unknown

CVE-2020-9987

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofing.
Attacker Value
Unknown

CVE-2020-5679

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.
Attacker Value
Unknown

CVE-2020-4785

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 189219.